113 vulnerabilities across 15 products scored HIGH or above on August 11, 2026.
- π£ EMERGENCY: 1
- π΄ CRITICAL: 47
- π HIGH: 65
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-72886 (dokploy/dokploy) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72882 (dokploy/dokploy) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72901 (dokploy/dokploy) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-72737 (dokploy/dokploy) β F1: exploitable β functional, AAS: 9.7 β 11.7 (HIGH β HIGH). Originally in 2026-08-10 bulletin.
- [UPGRADED] CVE-2026-71558 (apache/fory) β F1: exploitable β functional, AAS: 10.9 β 12.9 (HIGH β CRITICAL). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-62873 (microsoft/microsoft_365_admin_center) β F1: theoretical β poc, AAS: 9.1 β 11.6 (HIGH β HIGH). Originally in 2026-08-07 bulletin.
- [UPGRADED] CVE-2026-65507 (flavor/aiwu) β F1: exploitable β functional, AAS: 10.9 β 12.9 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-5430 (wso2/api_control_plane) β F1: theoretical β poc, AAS: 10.7 β 13.2 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-34191 (apache/apr-util) β F1: exploitable β functional, AAS: 10.5 β 13.7 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-28139 (ajax_search_lite/ajax_search_lite) β F1: exploitable β functional, AAS: 10.1 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2025-15039 (wso2/api_control_plane) β F1: theoretical β itw, AAS: 9.9 β 13.9 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-65583 (apache/cxf) β F1: exploitable β functional, AAS: 9.9 β 11.9 (HIGH β HIGH). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-68079 (apache/cxf) β F1: theoretical β poc, AAS: 9.6 β 12.1 (HIGH β CRITICAL). Originally in 2026-08-06 bulletin.
- [UPGRADED] CVE-2026-48168 (mervinpraison/praisonai) β F1: exploitable β functional, AAS: 10.8 β 12.8 (HIGH β CRITICAL). Originally in 2026-08-05 bulletin.
- [UPGRADED] CVE-2026-70478 (flowiseai/flowise) β F1: theoretical β poc, AAS: 9.9 β 12.4 (HIGH β CRITICAL). Originally in 2026-08-04 bulletin.
π£ [EMERGENCY] adobe/coldfusion_2025
5 CVEs | CVSS 3.1: 10.0 | AAS 16.8
cpe:2.3:a:adobe:coldfusion_2025:*:*:*:*:*:*:*:*
Adobe ColdFusion 2025 is affected by five vulnerabilities, including multiple critical-severity flaws. The most severe carries a CVSS score of 10.0 and is an OS command injection that allows unauthenticated remote attackers to execute arbitrary code with changed scope, meaning compromise can extend beyond the vulnerable component itself. This vulnerability is confirmed exploited in the wild.
All organizations running Adobe ColdFusion 2025 should treat this as an emergency. Apply the patches referenced in Adobe advisory APSB26-90 immediately, prioritizing any internet-facing ColdFusion instances. If patching cannot be performed right away, consider taking affected servers offline or isolating them behind strict network controls until remediation is complete.
- π£ CVE-2026-48362 (CVSS 3.1: 10.0)
- π΄ CVE-2026-71387 (CVSS 3.1: 8.8)
- π CVE-2026-21279 (CVSS 3.1: 8.2)
- π CVE-2026-48440 (CVSS 3.1: 8.1)
- π CVE-2026-34635 (CVSS 3.1: 8.4)
π΄ [CRITICAL] microsoft/windows
78 CVEs | CVSS 3.1: 9.8 | AAS 14.6
cpe:2.3:a:microsoft:windows:*:*:*:*:*:*:*:*cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*(< 10.0.14393.9418)cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*(< 10.0.14393.9418)cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*(< 10.0.17763.9115)cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*(< 10.0.17763.9115)
Microsoft Windows is affected by 78 vulnerabilities in the August 2026 update cycle, including multiple critical-severity flaws. The most severe carries a CVSS score of 9.8 and is a heap-based buffer overflow in the Windows iSCSI Target Service that allows an unauthenticated remote attacker to execute arbitrary code over the network. Active exploitation in the wild has been confirmed.
All organizations running Windows should prioritize this month’s security updates immediately. Given the volume of vulnerabilities and confirmed in-the-wild exploitation, security teams should expedite patch deployment across all Windows systems, with particular urgency for servers running the iSCSI Target Service or any network-exposed roles. Consult the Microsoft Security Response Center update guide for the full list of affected components and remediation guidance.
- π΄ CVE-2026-65791 (CVSS 3.1: 9.8)
- π΄ CVE-2026-62893 (CVSS 3.1: 9.8)
- π΄ CVE-2026-62878 (CVSS 3.1: 9.8)
- π΄ CVE-2026-62822 (CVSS 3.1: 8.8)
- π΄ CVE-2026-54984 (CVSS 3.1: 7.8)
- π΄ CVE-2026-62785 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62823 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62816 (CVSS 3.1: 8.8)
- π΄ CVE-2026-49179 (CVSS 3.1: 8.8)
- π΄ CVE-2026-65681 (CVSS 3.1: 7.5)
- π΄ CVE-2026-65775 (CVSS 3.1: 7.8)
- π΄ CVE-2026-65789 (CVSS 3.1: 8.1)
- π΄ CVE-2026-62784 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62824 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62818 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62795 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62817 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62790 (CVSS 3.1: 8.8)
- π΄ CVE-2026-62815 (CVSS 3.1: 9.8)
- π΄ CVE-2026-62800 (CVSS 3.1: 8.8)
- π΄ CVE-2026-61937 (CVSS 3.1: 7.8)
- π΄ CVE-2026-62717 (CVSS 3.1: 7.8)
- π CVE-2026-59132 (CVSS 3.1: 7.5)
- π CVE-2026-61353 (CVSS 3.1: 7.8)
- π CVE-2026-65679 (CVSS 3.1: 8.1)
- π CVE-2026-62889 (CVSS 3.1: 8.1)
- π CVE-2026-62770 (CVSS 3.1: 7.8)
- π CVE-2026-62752 (CVSS 3.1: 7.8)
- π CVE-2026-65787 (CVSS 3.1: 7.8)
- π CVE-2026-65774 (CVSS 3.1: 7.8)
- π CVE-2026-62707 (CVSS 3.1: 7.8)
- π CVE-2026-42976 (CVSS 3.1: 7.8)
- π CVE-2026-61364 (CVSS 3.1: 7.8)
- π CVE-2026-65671 (CVSS 3.1: 7.8)
- π CVE-2026-62768 (CVSS 3.1: 7.8)
- π CVE-2026-65814 (CVSS 3.1: 7.8)
- π CVE-2026-62741 (CVSS 3.1: 7.8)
- π CVE-2026-61925 (CVSS 3.1: 7.8)
- π CVE-2026-62735 (CVSS 3.1: 7.8)
- π CVE-2026-62754 (CVSS 3.1: 7.8)
- π CVE-2026-62701 (CVSS 3.1: 7.8)
- π CVE-2026-62761 (CVSS 3.1: 7.8)
- π CVE-2026-62807 (CVSS 3.1: 7.8)
- π CVE-2026-65786 (CVSS 3.1: 7.8)
- π CVE-2026-62812 (CVSS 3.1: 7.8)
- π CVE-2026-62890 (CVSS 3.1: 7.8)
- π CVE-2026-61926 (CVSS 3.1: 7.8)
- π CVE-2026-62692 (CVSS 3.1: 7.8)
- π CVE-2026-62732 (CVSS 3.1: 7.8)
- π CVE-2026-62877 (CVSS 3.1: 7.8)
- π CVE-2026-62778 (CVSS 3.1: 8.1)
- π CVE-2026-62820 (CVSS 3.1: 8.1)
- π CVE-2026-62755 (CVSS 3.1: 7.8)
- π CVE-2026-62803 (CVSS 3.1: 7.8)
- π CVE-2026-62700 (CVSS 3.1: 7.8)
- π CVE-2026-62758 (CVSS 3.1: 7.8)
- π CVE-2026-61349 (CVSS 3.1: 7.8)
- π CVE-2026-62777 (CVSS 3.1: 7.8)
- π CVE-2026-62894 (CVSS 3.1: 7.8)
- π CVE-2026-62711 (CVSS 3.1: 7.8)
- π CVE-2026-62710 (CVSS 3.1: 7.8)
- π CVE-2026-66799 (CVSS 3.1: 7.8)
- π CVE-2026-62719 (CVSS 3.1: 7.8)
- π CVE-2026-62712 (CVSS 3.1: 7.8)
- π CVE-2026-65790 (CVSS 3.1: 7.8)
- π CVE-2026-62885 (CVSS 3.1: 7.8)
- π CVE-2026-62747 (CVSS 3.1: 7.8)
- π CVE-2026-62819 (CVSS 3.1: 8.1)
- π CVE-2026-62797 (CVSS 3.1: 7.8)
- π CVE-2026-62781 (CVSS 3.1: 8.1)
- π CVE-2026-62776 (CVSS 3.1: 7.8)
- π CVE-2026-59127 (CVSS 3.1: 7.8)
- π CVE-2026-61930 (CVSS 3.1: 7.8)
- π CVE-2026-62696 (CVSS 3.1: 7.8)
- π CVE-2026-62792 (CVSS 3.1: 8.1)
- π CVE-2026-61932 (CVSS 3.1: 7.8)
- π CVE-2026-61367 (CVSS 3.1: 7.8)
- π CVE-2026-61365 (CVSS 3.1: 7.8)
π΄ [CRITICAL] microsoft/visual_studio_code
6 CVEs | CVSS 3.1: 8.8 | AAS 14.2
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Microsoft Visual Studio Code is affected by six vulnerabilities, including multiple critical-severity OS command injection flaws that allow an unauthenticated attacker to execute arbitrary code remotely. The most severe carries a CVSS score of 8.8, and active exploitation in the wild has been confirmed.
Development teams and organizations with widespread VS Code deployments should update to the latest version immediately. Given VS Code’s extensive use across software development environments and its deep integration with source code and credentials, compromised installations pose significant supply chain risk. Consult the Microsoft Security Response Center advisory for full details and ensure auto-update is enabled across managed endpoints.
- π΄ CVE-2026-69320 (CVSS 3.1: 8.8)
- π΄ CVE-2026-59113 (CVSS 3.1: 8.8)
- π΄ CVE-2026-70336 (CVSS 3.1: 8.8)
- π΄ CVE-2026-69278 (CVSS 3.1: 7.8)
- π΄ CVE-2026-69306 (CVSS 3.1: 8.2)
- π CVE-2026-58650 (CVSS 3.1: 7.8)
π΄ [CRITICAL] adobe/adobe_commerce
4 CVEs | CVSS 3.1: 9.1 | AAS 13.8
cpe:2.3:a:adobe:adobe_commerce:*:*:*:*:*:*:*:*
Adobe Commerce is affected by four vulnerabilities, including multiple critical-severity flaws. The most severe carries a CVSS score of 9.1 and is an incorrect authorization issue that allows an unauthenticated attacker to escalate privileges and access sensitive resources without user interaction. Proof-of-concept exploit code is publicly available, increasing the likelihood of near-term exploitation.
Organizations running Adobe Commerce or Magento Open Source should apply the patches referenced in Adobe advisory APSB26-92 as a high priority. E-commerce platforms are frequent targets for payment data theft and web skimming attacks, making prompt remediation essential for any internet-facing storefront.
- π΄ CVE-2026-71362 (CVSS 3.1: 9.1)
- π΄ CVE-2026-48413 (CVSS 3.1: 8.7)
- π CVE-2026-48416 (CVSS 3.1: 7.5)
- π CVE-2026-48415 (CVSS 3.1: 7.6)
π΄ [CRITICAL] adobe/adobe_campaign_classic
3 CVEs | CVSS 3.1: 10.0 | AAS 13.7
cpe:2.3:a:adobe:adobe_campaign_classic:*:*:*:*:*:*:*:*
Adobe Campaign Classic (ACC) is affected by three vulnerabilities, including multiple critical-severity flaws. The most severe carries a CVSS score of 10.0 and is an incorrect authorization issue that allows an unauthenticated attacker to execute arbitrary code with changed scope, meaning compromise can extend beyond the vulnerable application itself. A functional exploit is known to exist, making active exploitation highly probable if not already underway.
Organizations using Adobe Campaign Classic for marketing automation and email campaigns should treat this as an emergency and apply the patches referenced in Adobe advisory APSB26-123 immediately. Given that ACC deployments typically hold large volumes of customer data and have network connectivity to email infrastructure, a compromised instance presents severe data breach and lateral movement risk.
- π΄ CVE-2026-27302 (CVSS 3.1: 10.0)
- π΄ CVE-2026-71398 (CVSS 3.1: 10.0)
- π CVE-2026-48381 (CVSS 3.1: 9.0)
π΄ [CRITICAL] microsoft/powershell_7.4
2 CVEs | CVSS 3.1: 8.8 | AAS 13.6
cpe:2.3:a:microsoft:powershell_7.4:*:*:*:*:*:*:*:*
Microsoft PowerShell 7.4 is affected by two vulnerabilities, including at least one critical-severity relative path traversal flaw that allows an unauthenticated attacker to execute arbitrary code over a network. The most severe carries a CVSS score of 8.8, and active exploitation in the wild has been confirmed.
Organizations using PowerShell 7.4 across Windows, Linux, or macOS systems should update immediately. PowerShell is widely used in automation, CI/CD pipelines, and system administration, so compromised installations can provide attackers with broad access to infrastructure. Consult the Microsoft Security Response Center advisory for patching guidance and verify that all managed systems are running the latest corrected version.
- π΄ CVE-2026-70337 (CVSS 3.1: 8.8)
- π΄ CVE-2026-70338 (CVSS 3.1: 7.8)
π΄ [CRITICAL] craftcms/cms
4 CVEs | CVSS 4.0: 9.3 | AAS 13.5
cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*
Craft CMS is affected by four vulnerabilities, including multiple critical-severity authorization flaws. The most severe carries a CVSS 4.0 score of 9.3 and allows control panel users with limited view-only permissions to perform unauthorized modifications to category structures due to incorrect permission checks. Proof-of-concept exploit code is publicly available for these issues.
Organizations running Craft CMS versions 5.0.0-RC1 through 5.10.5 should update to the latest patched release immediately. Even in environments where control panel access is restricted to trusted users, these authorization bypasses undermine the intended privilege model and could enable unauthorized content manipulation or further escalation. Consult the vendor advisory on GitHub for affected versions and remediation details.
- π΄ CVE-2026-72785 (CVSS 4.0: 9.3)
- π΄ CVE-2026-72778 (CVSS 4.0: 8.7)
- π΄ CVE-2026-72779 (CVSS 4.0: 8.7)
- π CVE-2026-72781 (CVSS 4.0: 8.7)
π΄ [CRITICAL] libgit2/libgit2
1 CVE | CVSS 4.0: 9.4 | AAS 13.5
cpe:2.3:a:libgit2:libgit2:*:*:*:*:*:*:*:*
Libgit2 versions 0.27.0 through 1.9.0 built with the libssh2 SSH backend contain a critical shell command injection vulnerability with a CVSS 4.0 score of 9.4. The flaw allows remote attackers to execute arbitrary commands on an SSH server by crafting a repository path with unescaped shell metacharacters, as the library inserts paths directly into shell command strings without sanitization. Active exploitation in the wild has been confirmed.
Any organization using libgit2 directly or through downstream dependencies such as language bindings, Git clients, CI/CD tools, or package managers should determine exposure immediately and update to a patched release. Given libgit2’s widespread embedding in development tooling, the attack surface may be broader than expected. Consult the vendor’s GitHub repository for the latest fixed version and verify whether your builds use the affected libssh2 backend.
- π΄ CVE-2026-5917 (CVSS 4.0: 9.4)
π΄ [CRITICAL] mongodb/mongodb_server
1 CVE | CVSS 4.0: 9.0 | AAS 13.4
cpe:2.3:a:mongodb:mongodb_server:*:*:*:*:*:*:*:*
MongoDB Server is affected by a critical vulnerability with a CVSS 4.0 score of 9.0 involving intra-cluster authentication. An attacker with network access to replica set traffic can manipulate the authentication mechanism used between cluster members, potentially causing the shared internal credential to be transmitted in a weakened form. If recovered, this credential grants internal superuser access to all nodes in the deployment. Active exploitation in the wild has been confirmed.
Organizations running MongoDB replica sets or sharded clusters should patch immediately and review their deployments for signs of compromise. Rotate internal cluster authentication credentials after patching, and ensure intra-cluster network traffic is properly segmented and not exposed to untrusted networks. Consult the vendor advisory at the MongoDB Jira tracker for affected versions and remediation steps.
- π΄ CVE-2026-18691 (CVSS 4.0: 9.0)
π΄ [CRITICAL] eosphoros-ai/db-gpt
1 CVE | CVSS 4.0: 9.3 | AAS 13.2
cpe:2.3:a:eosphoros-ai:db-gpt:*:*:*:*:*:*:*:*
DB-GPT v0.8.1 is affected by a critical unauthenticated path traversal vulnerability with a CVSS 4.0 score of 9.3. The flaw allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint, enabling code execution through mechanisms such as Python startup hooks or cron directories. Active exploitation in the wild has been confirmed.
Organizations running DB-GPT should take exposed instances offline immediately and update to a patched version. Given that this is an AI/LLM platform often connected to databases containing sensitive data, a compromised instance poses significant risk of data exfiltration and lateral movement. Ensure DB-GPT is not directly exposed to the internet and consult the vendor’s GitHub repository for remediation guidance.
- π΄ CVE-2026-73034 (CVSS 4.0: 9.3)
π΄ [CRITICAL] chocobozzz/peertube
2 CVEs | CVSS 3.1: 9.8 | AAS 13.1
cpe:2.3:a:chocobozzz:peertube:*:*:*:*:*:*:*:*(< 8.2.2)
PeerTube, the ActivityPub-federated video streaming platform, is affected by two vulnerabilities prior to version 8.1.6, including at least one critical-severity SQL injection with a CVSS score of 9.8. The most severe flaw allows an unauthenticated remote server to inject SQL through an attacker-controlled ActivityPub actor inbox URL, enabling full read and write access to the database including OAuth access tokens and administrator account takeover. A functional exploit exists for this issue.
All PeerTube instance operators should upgrade to version 8.1.6 immediately. Because PeerTube instances federate with external servers by design, any internet-connected instance is directly exposed to exploitation without requiring any user interaction. After patching, administrators should rotate all OAuth tokens and review admin accounts for signs of unauthorized access.
- π΄ CVE-2026-73211 (CVSS 3.1: 9.8)
- π΄ CVE-2026-73090 (CVSS 3.1: 9.3)
π΄ [CRITICAL] seaweedfs/seaweedfs
3 CVEs | CVSS 3.1: 9.8 | AAS 13.1
cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:*:*:*(< 4.24)
SeaweedFS, a distributed storage system, is affected by three vulnerabilities prior to version 4.24, including multiple critical-severity flaws. The most severe carries a CVSS score of 9.8 and allows any unauthenticated client that can reach the filer gRPC port to invoke IAM management RPCs such as CreateUser, CreateAccessKey, and PutPolicy when JWT signing keys are not configured, granting full S3 administrative control over stored data. Proof-of-concept exploit code is publicly available.
Organizations running SeaweedFS versions prior to 4.24 should upgrade immediately and verify that JWT filer signing keys are properly configured. After patching, audit all IAM users, access keys, and policies for unauthorized entries that may have been created through exploitation. Restrict network access to the filer gRPC port to trusted hosts only as an additional layer of defense.
- π΄ CVE-2026-72920 (CVSS 3.1: 9.8)
- π΄ CVE-2026-73080 (CVSS 3.1: 9.3)
- π CVE-2026-72921 (CVSS 3.1: 8.1)
π΄ [CRITICAL] papersgpt/papersgpt-for-zotero
1 CVE | CVSS 4.0: 9.4 | AAS 13.0
cpe:2.3:a:papersgpt:papersgpt-for-zotero:*:*:*:*:*:*:*:*
PapersGPT for Zotero version 0.6.1 contains a critical remote code execution vulnerability with a CVSS 4.0 score of 9.4. The plugin passes unsanitized LLM responses directly to window.eval(), allowing attackers to execute arbitrary JavaScript in Zotero’s chrome-privileged context through prompt injection in PDFs, man-in-the-middle interception of API requests, or a malicious custom LLM endpoint. This grants full file system access, process execution, and access to all Zotero library data. Active exploitation in the wild has been confirmed.
Researchers and academics using the PapersGPT plugin for Zotero should disable or uninstall it immediately until a patched version is available. This is particularly dangerous in academic environments where users routinely open untrusted PDFs from external sources, any of which could contain prompt injection payloads that trigger code execution. Consult the vendor’s GitHub repository for update status and do not use custom or untrusted LLM endpoints with this plugin.
- π΄ CVE-2026-73032 (CVSS 4.0: 9.4)
π΄ [CRITICAL] harttle/liquidjs
1 CVE | CVSS 3.1: 10.0 | AAS 12.8
cpe:2.3:a:harttle:liquidjs:*:*:*:*:*:*:*:*
LiquidJS, a widely used Shopify and GitHub Pages compatible template engine, contains a critical arbitrary code execution vulnerability with a CVSS score of 10.0 in all versions prior to 10.26.0. An attacker who can supply or influence template content can execute arbitrary code on the server through crafted templates. A functional exploit exists for this issue.
Any application using LiquidJS to render user-supplied or untrusted template content should update to version 10.26.0 immediately. This is especially urgent for web applications, CMS platforms, and e-commerce sites where templates may be editable by end users or sourced from external inputs. Review your dependency tree, as LiquidJS may be included transitively through other packages.
- π΄ CVE-2026-45618 (CVSS 3.1: 10.0)
π΄ [CRITICAL] microsoft/azure_kubernetes_service
1 CVE | CVSS 3.1: 9.4 | AAS 12.7
cpe:2.3:a:microsoft:azure_kubernetes_service:-:*:*:*:*:*:*:*
Microsoft Azure Kubernetes Service (AKS) is affected by a critical missing authentication vulnerability with a CVSS score of 9.4. The flaw allows an unauthenticated attacker to elevate privileges over a network by accessing a critical function that lacks proper authentication controls. Active exploitation in the wild has been confirmed.
All organizations using Azure Kubernetes Service should consult the Microsoft Security Response Center advisory immediately and apply any available mitigations or updates. Given the central role AKS plays in container orchestration and cloud workloads, a privilege escalation at this level could grant attackers broad control over clustered applications and sensitive data. Review AKS cluster audit logs for signs of unauthorized access and ensure network policies restrict exposure of management interfaces.
- π΄ CVE-2026-50516 (CVSS 3.1: 9.4)